vulnerability
CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
Critical
Summary
CISA has added a critical vulnerability, CVE-2026-48907, to its Known Exploited Vulnerabilities catalog affecting the Widget Factory Joomla Content Editor (JCE) due to improper access control. This flaw allows for PHP code execution, and there is currently no public information on active exploitation. Federal Civilian Executive Branch (FCEB) agencies are being directed to apply the patch immediately.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
